Deploy Cortex Sensor
For Cortex organization admins and IT teams. Employees should use Set up Cortex Sensor after Cortex appears on their device.
How deployment works
- Chaos Labs will create the Cortex organization and designate an initial admin.
- The designated admin will sign in to cortex.chaoslabs.xyz and complete organization onboarding.
- During onboarding, the admin will download a
.pkgor.exefor the target devices. - The admin will coordinate with IT to distribute Sensor using a compatible mobile device management system.
- Employees will open Cortex and complete device sign-in and capture setup.
Organization creation is not self-service. Most employees receive Cortex through managed deployment.
Who owns each step
| Owner | Responsibility |
|---|---|
| Chaos Labs | Create the organization and designate the initial admin with your team |
| Organization admin | Complete organization onboarding, download installers, and coordinate dashboard access |
| IT or device admin | Deploy Cortex and manage device, keychain, network, process, and operating-system policies |
| Employee | Sign in, enable approved capture surfaces, and verify activity |
| Developer | Resolve conflicts between local services and Cortex ports |
One person may fill both admin and IT roles. Cortex dashboard roles do not grant operating-system or MDM access.
Before deployment
Before rollout, confirm that the organization has completed any required employee notice or consent process for monitored AI activity. Contact the Chaos Labs team if the organization needs a description of what Cortex captures.
Get the installer
Sign in as the designated admin
- Go to cortex.chaoslabs.xyz.
- Sign in with the account designated during organization creation.
- Complete organization onboarding.
- Confirm the organization and identity settings before distributing Sensor.
If the designated admin cannot access the organization, contact the Chaos Labs team before distributing a package or creating another organization.
Obtain the deployment package
The onboarding flow provides the installer for each operating system:
| Platform | Requirement | Package | Tested deployment method |
|---|---|---|---|
| macOS | Apple Silicon and macOS 12 or later | .pkg | Jamf |
| Windows | Windows 10 or 11 on x64 | .exe | Microsoft Intune |

The installers are signed, and the macOS package is notarized. Jamf has been tested for macOS and Microsoft Intune has been tested for Windows. Test other deployment methods with a pilot group before rollout.
Distribute the installer provided during organization onboarding. Cortex does not have a public download page.
Verify each download against the SHA-256 checksum shown in the installer dialog before distributing it. On macOS run shasum -a 256 Cortex.pkg; on Windows run Get-FileHash Cortex.exe -Algorithm SHA256. The value must match exactly; if it does not, discard the download and download the installer again.
Distribute with MDM
Deployment steps depend on your MDM:
- Add the Cortex
.pkgor.exeto the MDM. - Assign it to a pilot group of representative devices.
- Apply the operating-system, keychain, routing, certificate, and network policies required for the capture paths in your rollout.
- Confirm Cortex installs and opens without requiring the employee to run a separate installer.
- Restart the device after installation when practical. A restart is not normally required, but it can activate newly installed capture services and application settings.
- Provide employees with the organization domain and Set up Cortex Sensor.
Sensor can be installed on the macOS and Windows versions listed above. Capture-path availability differs by platform. Use Supported providers and surfaces to choose what to test. Some browsers, desktop apps, command-line tools, and MCP hosts must restart after installation or configuration.
Validate a pilot device
On at least one representative managed device for each target platform:
- Confirm MDM installed Cortex.
- Open Cortex as an employee would.
- Complete organization sign-in.
- Configure each capture path included in the rollout.
- Send one new prompt through each source.
- Confirm each prompt appears in Home → Activity.
- Confirm Cloud sync is Up to date, Workspace is Enrolled, and Backlog is 0.
- Confirm the synced activity is available to an authorized Cortex dashboard user.
- Restart any applications named by Cortex, then confirm their capture paths become active.
- Quit and restart Cortex cleanly, then confirm capture recovers as expected.
Before expanding the rollout, verify enrollment, source configuration, local capture, and workspace sync. A successful installation or Running status alone does not verify capture.
Enrollment issues
If Cortex finds no identity providers, confirm that the employee entered the correct organization domain. The organization admin should verify the identity settings.
If sign-in does not complete, send the organization domain, identity provider, work account, and approximate attempt time to the Chaos Labs team.
Managed-device issues
Browser capture may require permission to change routing or certificate trust. Organization Admin access cannot override keychain, certificate-store, endpoint-security, or device-management policy.
If Cortex shows Port owners, include the port and process details when contacting the Chaos Labs team. Developers running local services can use Fix Sensor port conflicts.
Rollout and fleet operations
Fleet is limited to organization admins. Use it to:
- Filter endpoints by All endpoints, Not reporting, Never reported, or Healthy.
- Review Device, Person, Team, Last heartbeat, Last captured, Sensor version, State, Issue, and Action.
- Select Get installer to reopen the organization installer flow.
- Refresh the view after a deployment or repair.

Enrollment and revocation happen outside Fleet. Contact the Chaos Labs team for revocation or other device-lifecycle actions that are not available in the dashboard.
Offboard or replace a device
For organization offboarding or service termination:
- Export your organization's Cortex data during the service term or within 30 days after termination.
- Resolve any unsynced local backlog before removing Cortex.
- On each device, open Proxy → Browser & Desktop, select Web apps → Configure, and turn off Web routing and Certificate for Chrome. Then select Stop Cortex and remove Cortex through the MDM or approved device-management path. Stopping or quitting Cortex alone does not remove browser routing or certificate trust.
After the 30-day export window, Cortex data may be irretrievably erased.
See Control capture and sync for Sensor controls.
Contact the Chaos Labs team before removing a device that has an unsynced backlog or cannot be disconnected normally.